Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9048 | Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3. |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-001 |
|
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Email Tfa Project
Email Tfa Project email Tfa |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:email_tfa_project:email_tfa:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Email Tfa Project
Email Tfa Project email Tfa |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3. | |
| Title | Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001 | |
| Weaknesses | CWE-1390 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-06-19T22:42:50.725Z
Reserved: 2025-03-31T21:30:04.614Z
Link: CVE-2025-31676
Updated: 2025-04-29T15:43:32.233Z
Status : Analyzed
Published: 2025-03-31T22:15:20.113
Modified: 2025-06-04T15:03:00.780
Link: CVE-2025-31676
No data.
OpenCVE Enrichment
No data.
EUVD